Dreg (therealdreg)

therealdreg

User data from Github https://github.com/therealdreg

Company:rootkit.es

Location:Spain

Home Page:https://www.rootkit.es

GitHub:@therealdreg

Twitter:@therealdreg


Organizations
bochs-emu
x64dbg

Dreg's repositories

DbgChild

Debug Child Process Tool (auto attach)

Language:CLicense:NOASSERTIONStargazers:297Issues:20Issues:7

shellex

C-shellcode to hex converter, handy tool for paste & execute shellcodes in IDA PRO, gdb, windbg, radare2, ollydbg, x64dbg, immunity debugger & 010 editor

Language:CLicense:MITStargazers:115Issues:3Issues:0

enyelkm

LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry.

Language:CLicense:MITStargazers:86Issues:4Issues:0

x86osdev

x86 OS development using Bochs emulator. MIT xv6, JamesM's kernel development tutorials (with some changes) & more

Language:C++Stargazers:82Issues:4Issues:0

cgaty

Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)

Language:CLicense:MITStargazers:70Issues:8Issues:0

ida_vmware_windows_gdb

Helper script for Windows kernel debugging with IDA Pro on VMware + GDB stub (including PDB symbols)

Language:PythonLicense:GPL-3.0Stargazers:63Issues:9Issues:1

lsrootkit

Rootkit Detector for UNIX

Language:CLicense:MITStargazers:61Issues:10Issues:0

phook

Full DLL Hooking, phrack 65

Language:CLicense:MITStargazers:53Issues:8Issues:0

xshellex

With xshellex you can paste any kind of c-shellcode strings in x64dbg, ollydbg & immunity debugger

Language:CLicense:MITStargazers:39Issues:3Issues:0

linux_kernel_debug_disassemble_ida_vmware

Helper script for Linux kernel disassemble or debugging with IDA Pro on VMware + GDB stub (including some symbols helpers)

Language:PythonLicense:MITStargazers:36Issues:5Issues:0

evilmass_at90usbkey2

evil mass storage *AT90USBKEY2 (poc-malware-tool for offline system)

Language:CLicense:MITStargazers:31Issues:2Issues:0

nasm_linux_x86_64_pure_sharedlib

NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection

Language:ShellLicense:MITStargazers:29Issues:4Issues:0

auxlib

Full reversing of the Microsoft Auxiliary Windows API Library and ported to C

Language:CLicense:MITStargazers:24Issues:4Issues:0

PatchPae2_PatchPae3

PatchPae2 by wj32 and PatchPae3 by evgeny

The-GTK-Keylogger

The GTK Keylogger

Language:CStargazers:19Issues:2Issues:0

emuhookdetector

hook detector using emulation and comparing static with dynamic outputs

Language:CLicense:MITStargazers:17Issues:3Issues:1

ptrace_misconfiguration_local_privilege_escalation

ptrace misconfiguration Local Privilege Escalation

Language:CLicense:MITStargazers:11Issues:3Issues:0

nasm_vscode

nasm visual studio code

Language:ShellLicense:MITStargazers:10Issues:2Issues:0

dregshells

dregshells

Language:AssemblyLicense:MITStargazers:9Issues:3Issues:0

drx_ptrace_shellcode_injector

drx ptrace shellcode injector

Language:CLicense:MITStargazers:7Issues:4Issues:0

lufa-sdcard-mass-storagekeyboard-fatfs-AT90USBKEY2

lufa-sdcard-mass-storagekeyboard-fatfs-AT90USBKEY2

Language:CStargazers:7Issues:3Issues:0

python_reverse_shell_detached_background

python reverse shell detached background

License:MITStargazers:7Issues:5Issues:0

call_trick_r2pipe

radare2 script to fix disasm with call tricks for strings

License:MITStargazers:6Issues:4Issues:0

r2-syscall-printer

I created r2-syscall-printer (radare r2pipe script) because I need now Linux-kernel interface call convention support (x86 & x86_64): %rdi, %rsi, %rdx, %r10, %r8, %r9. Also you can use this tool as standalone-app to print syscall table info

Language:PythonLicense:MITStargazers:6Issues:4Issues:0

ringstepper

windbg plugin easy-step from user code to kernel code

Language:CLicense:MITStargazers:6Issues:3Issues:0

bochs-bed

Bochs Enhaced Debugger (bochs-bed). A modern console debug experience.

Language:C++License:MITStargazers:5Issues:4Issues:0

getproclib

Library for Windows Run-Time Dynamic Linking.

Language:CLicense:MITStargazers:4Issues:0Issues:0

AT90USBKEY2

Original sources and programs for AT90USBKEY2 + own code & patches

Language:HTMLLicense:MITStargazers:3Issues:3Issues:0

gdis

GDB plugin to debug instructions mixed with data (GDB-GEF support included)

Language:PythonLicense:MITStargazers:2Issues:2Issues:0

dreg-r2panels

my radare2 r2panels

License:MITStargazers:1Issues:3Issues:0